Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE Dovecot 23 Significant Memory Issues SUSE-SU-2026-1743-8

suse
Calendar Grey April 28, 2026
Dist Suse Esm H88
SUSE's important update for dovecot22 fixes multiple issues including memory and security vulnerabilities. Install now.
An update that solves seven vulnerabilities can now be installed.

Summary

## This update for dovecot22 fixes the following issues: * CVE-2025-59031: decode2text.sh OOXML extraction may follow symlinks and read unintended files during indexing (bsc#1260895). * CVE-2025-59032: pigeonhole: ManageSieve panic occurs with sieve-connect as a client (bsc#1260902). * CVE-2026-27855: OTP driver vulnerable to replay attack (bsc#1260900). * CVE-2026-27856: Doveadm credentials were not checked using timing-safe checking function (bsc#1260899). * CVE-2026-27857: sending excessive parenthesis causes imap-login to use excessive memory (bsc#1260898). * CVE-2026-27858: pigeonhole: managesieve-login can allocate large amount of memory during authentication (bsc#1260901). * CVE-2026-27859: excessive RFC 2231 MIME parameters in email would can excessive CPU usage (bsc#1260897).

References

* bsc#1260895

* bsc#1260897

* bsc#1260898

* bsc#1260899

* bsc#1260900

* bsc#1260901

* bsc#1260902

Cross-

* CVE-2025-59031

* CVE-2025-59032

* CVE-2026-27855

* CVE-2026-27856

* CVE-2026-27857

* CVE-2026-27858

* CVE-2026-27859

CVSS scores:

* CVE-2025-59031 ( SUSE ): 6.9

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

* CVE-2025-59031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

* CVE-2025-59031 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

* CVE-2025-59032 ( SUSE ): 8.7

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

* CVE-2025-59032 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-59032 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-27855 ( SUSE ): 7.6

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:1641-1
Release Date: 2026-04-28T11:53:50Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here